Executive brief
SourceCodester Best Employee Management System is a web-based HR application used for managing employee records and profiles. A vulnerability in the file upload directory allows attackers to view the contents of the /assets/uploadImage/Profile/ directory, potentially exposing employee profile images and related data through directory listing.
Technical details
The vulnerability is an information disclosure issue caused by inadequate access controls on the /assets/uploadImage/Profile/ directory. The directory listing feature is enabled, allowing unauthenticated or remote attackers to enumerate and access files stored in this location without proper authorization. The vulnerability can be triggered remotely over the network without requiring authentication. An attacker can list directory contents and potentially download sensitive files such as employee profile pictures and related metadata, leading to exposure of personally identifiable information (PII).
Affected products
- SourceCodester Best Employee Management System 1.0
Timeline
- 2026-08-17: disclosed